Paste any link and see what's riding along with it: tracking IDs, your own email address, session tokens, and whether that shared document link gives people edit access. Then copy the clean version.
The one that actually bites: sharing a Google Docs edit link instead of a view link. The tracking parameters are just the ones you notice.
Can: identify tracking parameters and which ones single you out personally; find email addresses,
tokens and session identifiers sitting in the query string; decode punycode and flag look-alike domains;
spot credentials embedded as user:pass@host; and tell a Google, Notion, Figma, Dropbox or
Airtable edit link from a view link.
Can't: follow a shortened link to its destination. Doing that means making the request, and a browser can't read the redirect of another site, so Kelpie flags shorteners and stops there rather than quietly pretending. It also can't know whether a domain is malicious; it only reports what the URL text itself gives away.
"No findings" means nothing was visible in the URL. It is not a verdict that a link is safe to open.